Vulnerabilidades em Red Hat

2.048 resultados
Análise Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2020-1697MEDIUMIt was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not valiEPSS 0.8%CVE-2025-32914HIGHLibsoup: oob read on libsoup through function "soup_multipart_new_from_message" in soup-multipart.c leads to crash or exit of processEPSS 0.8%CVE-2024-8676HIGHCri-o: checkpoint restore can be triggered from different namespacesEPSS 0.8%CVE-2026-66793HIGHGovernance-policy-addon-controller: governance-policy-addon-controller: arbitrary container image override via managedclusteraddon annotation enables rce on spokeEPSS 0.8%CVE-2026-44190HIGHAnsible-lightspeed: ansible lightspeed visual studio code extension: arbitrary code execution via command injection in activation script settingEPSS 0.8%CVE-2020-10689MEDIUMA flaw was found in the Eclipse Che up to version 7.8.x, where it did not properly restrict access to workspace pods. An authenticated user EPSS 0.8%CVE-2025-32050MEDIUMLibsoup: integer overflow in append_param_quotedEPSS 0.8%CVE-2025-6193MEDIUMTrustyai-explainability: command injection via lmevaljob crEPSS 0.7%CVE-2017-7538LOWA cross-site scripting (XSS) flaw was found in how an organization name is displayed in Satellite 5, before 5.8. A user able to change an orEPSS 0.7%CVE-2025-0620MEDIUMSamba: smbd doesn't pick up group membership changes when re-authenticating an expired smb sessionEPSS 0.7%CVE-2023-5215MEDIUMLibnbd: crash or misbehaviour when nbd server returns an unexpected block sizeEPSS 0.7%CVE-2026-18948CRITICALFeast: feast: unsafe dill deserialization of registry-stored udfs — rce on feature server and registry serverEPSS 0.7%CVE-2023-6787MEDIUMKeycloak: session hijacking via re-authenticationEPSS 0.7%CVE-2026-7307HIGHKeycloak: keycloak: denial of service via specially crafted saml inputEPSS 0.7%CVE-2019-14885MEDIUMA flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA. Confidential information of the system property's security aEPSS 0.7%CVE-2019-14905HIGHA vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in AnsibEPSS 0.7%CVE-2026-7374CRITICALKubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerabilityEPSS 0.7%CVE-2026-3832LOWGnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp responseEPSS 0.7%CVE-2026-66786CRITICALSubmariner: submariner: ipsec.conf stanza injection via remote-supplied cablename and subnetsEPSS 0.7%CVE-2023-6841HIGHKeycloak: amount of attributes per object is not limited and it may lead to dosEPSS 0.7%